International Cyber Digest
3.4K subscribers
176 photos
11 videos
2 files
22 links
Your weekly go-to cybersecurity newsletter, curated and commented on by our senior analysts.
Download Telegram
Media is too big
VIEW IN TELEGRAM
❗️ A scammer was caught using an AI face mask to hide his true identity.

He works for a fake company called "Global Metrix", which offers recovery services for stolen crypto.
🀣19❀1😁1😭1
Me meeting up with my insiders for status updates on recent supply chain attacks.
🀣10😁8❀4πŸ”₯1
πŸš¨β€ΌοΈ MAJOR SUPPLY CHAIN ATTACK: npm package axios is compromised after the maintainer's npm account was hijacked.

Malicious versions contain a Remote Access Trojan. axios has 100M+ weekly downloads β€” it's in practically everything.

If you have installed [email protected] or [email protected], assume compromise.

Axios' lead maintainer jasonsaayman's npm account was compromised β€” email was swapped to an anonymous Proton Mail address.

Both malicious versions were pushed manually via npm CLI, bypassing GitHub Actions OIDC entirely, without commits.

πŸ”΄ Stepsecurity report: https://stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan

πŸ”΄ Socket report:
https://socket.dev/blog/axios-npm-package-compromised
❀8πŸ₯΄2
πŸš¨β€ΌοΈ BREAKING: Claude Code's source code has been leaked via a map file exposed in Anthropic's npm registry.

The leaked code appears to reveal new and previously undisclosed features.

Source code backups:

1)
https://github.com/chatgptprojects/claude-code

2)
https://pub-aea8527898604c1bbb12468b1581d95e.r2.dev/src.zip
πŸ‘12😱6❀5😁3
Claude Code uses axios btw πŸ₯΄
😭15😁4πŸ₯΄2
Forget the Strait of Hormuz. The world economy now relies on the compromised lead axios maintainer finding a GitHub contact on X...
😁12😭7πŸ”₯2
Ain’t no npm package crisis complete without this meme πŸ˜‚
Please open Telegram to view this post
VIEW IN TELEGRAM
🀣21😁3
‼️ Meet the guy almost everyone loves for alerting the axios devs about the supply chain attack.

He built a supply chain monitoring system last week, and was alerted within minutes of the axios compromise.

The world should be thanking Elastic Security's finest:
Joe
X:dez_
🀣8❀1